by lunarg on June 3rd 2015, at 15:47

As long as there are 2003 domain controllers in your network, your old NT4 workstations will be able to authenticate against your domain. As soon as you migrate those 2003's out of the network, you'll run into trouble. By default, Server 2008 R2 no longer accepts authentication requests from NT4 because they use cryptography that's too old and unsafe.

The best solution is to get rid of those NT4 machines, but if that's not possible, you can re-enable support for cryptography on your DCs through GPO.

  1. Either edit the Default Domain Controller Policy group policy, or create a new GPO in the Domain Controllers OU.
  2. Edit the GPO and navigate to: Computer Configuration > Administrative Templates > System > Net Logon.
  3. Set Allow cryptography algorithms compatible with Windows NT 4.0 to Enabled.
  4. Optionally, run gpupdate on each of the DCs to immediately apply the policy change.

For more information, see KB 942564.

